logo

Researchers Sidestep Paypal Two-Factor Authentication

ID: 6ec021d0-a41a-5a5d-bf3f-7c8306d95f7a

STIX ID: report--6ec021d0-a41a-5a5d-bf3f-7c8306d95f7a

Feed Name: Security Ledger

Threat Score
55/100

Date Published: 2014-06-25

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

DUO Security researchers disclosed a vulnerability in PayPal's mobile API that can nullify the Security Key two-factor authentication: because two-factor enforcement was performed on the client rather than the server, an attacker who already has a PayPal username and password could log in via the mobile API without the second factor. PayPal has applied a workaround and is working on a permanent fix; there is no mention of active exploitation in the wild in this report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.